CVE-2023-46510: Zioncom a7000r Firmware

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.

Affected products

  • Zioncom a7000r Firmware: version 4.1cu.4154 only

Published 2023-10-27. Last modified 2026-06-17.